opentrade-portfolio
Warn
Audited by Socket on Mar 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's portfolio-checking behavior and token requirement fit its stated purpose, but its execution model relies on repeated raw GitHub pipe-to-shell installation of an external CLI and then passes API credentials to that CLI. The main concern is supply-chain and credential-forwarding trust, not clear evidence of malicious intent.
Confidence: 81%Severity: 74%
Audit Metadata